HIGHSupply Chain
Verified
Global

Cl0p Mass Exploits Cleo File Transfer Zero-Day — 600+ Organizations Hit

·Source: Huntress / Cleo Advisory

Updated:

Executive Summary

Cl0p launches fourth major file transfer campaign exploiting Cleo Harmony, VLTrader, and LexiCom zero-day. Systematic data exfiltration ongoing.

Analysis

CVE-2026-27891 is a deserialization flaw in Cleo products allowing unauthenticated RCE. Huntress detected exploitation March 18. Over 600 organizations compromised. This is Cl0p fourth file transfer campaign after Accellion, GoAnywhere, and MOVEit.

Timeline

Discovered
Mar 18, 2026
Exploitation Detected
Mar 18, 2026
Published
Mar 22, 2026
Patch Available
Mar 21, 2026

Indicators of Compromise (1)

CVE (1)
CVE-2026-27891
Source Attribution

Originally published by Huntress / Cleo Advisory on Mar 22, 2026. Verified by: Huntress, CISA, Cleo.

Related Threats

LOWSupply Chain

Unsloth’s model picker had a code-execution problem

True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines. Pillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the model repository. This could potentially allow attackers to use a speci

CSO Online
LOWSupply Chain

OpenAI pulls the plug on GPT 6.1 Astra as agents keep crossing lines

OpenAI has scrapped the planned October release of GPT-6.1 Astra after internal testing found the model did not meet the company’s safety and alignment standards. GPT-6.1 Astra was being developed as a more autonomous model capable of handling complex tasks with less human assistance, and was expected to be integrated into ChatGPT and Codex. But internal testing found that it could evade oversight

CSO Online
MEDIUMSupply Chain

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the victims to groups without their consent," OX Security researchers Nir Zadok, Moshe Siman Tov Bustan, and Vitalii Chepurko said in a technical

The Hacker News